Md Rasel Bhuyan
51 posts

Md Rasel Bhuyan
@Mdrasel1230
I am a Student, Self learner, CTF player and I love cyber security ❤️ErrOr SquaD❤️
Dhaka, Bangladesh Katılım Kasım 2016
404 Takip Edilen152 Takipçiler

H1-213/My First Ever Live Hacking Event
It was fun to hack Amazon, Thanks @Hacker0x01 & @Amazon :)
#h1213 #hackforgood #togetherwehitharder




English

More secure Facebook Canvas Part 2: $100k worth of Account Takeovers:
ysamm.com/?p=742
As usual, simple but critical.
English

It looks like Microsoft finally fixed all my Exchange vulnerabilities (including Pwn2Own bugs) !
Here is a small spoiler - You can't imagine how amazing it is when I found Exchange still suffered from Padding Oracle Attack 😻 - #proxylogon-is-just-the-tip-of-the-iceberg-a-new-attack-surface-on-microsoft-exchange-server-23442" target="_blank" rel="nofollow noopener">blackhat.com/us-21/briefing…
#BHUSA #DEFCON
English

Yay, my talk is accepted by Black Hat USA!
"... 7 vulnerabilities that consist of server-side, client-side, and crypto bugs were found via this attack surface and chained into 3 different attack scenarios: ProxyLogon, ProxyShell and ProxyOracle!" #proxylogon-is-just-the-tip-of-the-iceberg-a-new-attack-surface-on-microsoft-exchange-server-23442" target="_blank" rel="nofollow noopener">blackhat.com/us-21/briefing… #BHUSA

English

Account takeover of Instagram accounts due to unrestricted permissions of third-party application's generated tokens ( $18K ) :
ysamm.com/?p=684
English

Here's the third bug. Multiple bugs were chained to achieve Facebook account takeover.
Facebook account takeover due to unsafe redirects after the OAuth flow ( $30k )
ysamm.com/?p=667
Youssef Sammouda (sam0)@samm0uda
I had a crazy week in February in which i was able to find 3 interesting account takeovers in Facebook and resulted a total of $100k in bounties. I'm sharing details about two of them and soon the third: ysamm.com/?p=646 ysamm.com/?p=654
English

Just like OSCP, my OSWE has also been a fast-paced journey of only 30 days and passing it on the 1st attempt! Sharing my #OSWE experience in a few words and some tips and pointers for someone willing to take on the course:
rayhan0x01.github.io/web/2021/04/12…
English

I am ecstatic to share that I passed the #OSWE exam on my 1st attempt! The 48h long exam was the most thrilling exam I went through so far. Loved the course contents and especially the extra lab machines were super fun! Thanks for such a neat course @offsectraining
#ITriedHarder

English


Just got my first $10k bounty on @Hacker0x01.
Bug: The site was trying to add document from AWS bucket to the main site with POST request,it contains Param named KEY with URL path as value. I tried directory traversal on that param,and it dislcose full bucket with credentials.

English







